User behavior anomaly detection method, electronic equipment, storage medium and program product
By acquiring target dimensions and indicator values of user behavior within a target time window, constructing behavioral baseline data for anomaly detection, this technology solves the problems of high false alarm rate and slow detection speed in existing technologies, achieving fast and accurate detection of user behavior anomalies and meeting the rapid response needs of enterprise audits.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-29
- Publication Date
- 2026-04-03
AI Technical Summary
Existing user behavior anomaly detection technologies suffer from high false alarm rates and slow detection speeds, making it difficult to meet the rapid response needs of enterprise auditing work.
By acquiring target dimensions and multiple indicator values within the target time window as historical behavioral data, behavioral baseline data is constructed. Anomaly detection is then performed based on the behavioral baseline data, improving data quality and adapting to different individual users, thereby quickly and accurately obtaining anomaly detection results for target behaviors.
It reduces the false alarm rate of abnormal user behavior detection results, improves detection speed, and can quickly respond to the management needs of audit work, meeting the control requirements of enterprise audit.
Smart Images

Figure CN121786694A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of user behavior auditing technology, and in particular to a method for detecting abnormal user behavior, an electronic device, a storage medium, and a program product. Background Technology
[0002] With the development of information and digital technologies, the management and operation methods of enterprise auditing have undergone significant changes. Current auditing systems mainly rely on ERP and PMIS systems, which suffer from low auditing efficiency, weak comparative analysis capabilities, and can only perform post-audit results, failing to achieve intelligent risk identification, analysis, and early warning functions. Among related technologies, those for detecting abnormal user behavior suffer from high false alarm rates and slow detection speeds, making it difficult to meet the management and rapid response needs of enterprise auditing. Summary of the Invention
[0003] In view of this, one objective of the embodiments of this application is to provide a method, electronic device, storage medium and program product for detecting abnormal user behavior, in order to solve the technical problems of high false alarm rate and slow detection speed of abnormal user behavior detection results in related technologies.
[0004] To address the aforementioned technical problems, this application provides the following technical solutions: On the one hand, embodiments of this application provide a method for detecting abnormal user behavior, the method comprising: Acquire historical behavior data, which includes the target dimension and multiple indicator values of the target dimension within the target time window. The target dimension is the detection dimension corresponding to the user's target behavior. Based on historical behavioral data, behavioral baseline data is obtained. The behavioral baseline data is used to characterize the data quality and distribution characteristics of indicator values of historical behavioral data. Based on behavioral baseline data, anomaly detection results for the target behavior are obtained.
[0005] On the other hand, embodiments of this application provide an electronic device, including: A processor and a memory communicatively connected to the processor; The memory stores computer program instructions executable by the processor, which, when executed by the processor, cause the electronic device to perform any of the user behavior anomaly detection methods proposed in the first aspect.
[0006] On the other hand, embodiments of this application provide a computer-readable storage medium storing processor-executable computer program instructions, which, when executed by a processor, cause the computer to perform any of the user behavior anomaly detection methods proposed in the first aspect.
[0007] On the other hand, embodiments of this application provide a computer program product, the computer program product including a computer program stored on a computer-readable storage medium, the computer program including a program or instructions, which, when executed by an electronic device, cause the electronic device to perform any of the user behavior anomaly detection methods proposed in the first aspect.
[0008] The embodiments of this application have the following beneficial effects: Unlike related technologies, the user behavior anomaly detection method provided in the embodiments of this application includes: acquiring historical behavior data, the historical behavior data including a target dimension and multiple indicator values of the target dimension within a target time window, the target dimension being the detection dimension corresponding to the user's target behavior; obtaining behavior baseline data based on the historical behavior data, the behavior baseline data being used to characterize the data quality and indicator value distribution characteristics of the historical behavior data; and obtaining anomaly detection results of the target behavior based on the behavior baseline data.
[0009] This application embodiment selects the target dimension and multiple indicator values of the target dimension corresponding to the user's target behavior within the target time window as historical behavior data, thereby improving data quality and adapting to different individual users. Based on the indicator values of the target dimension, accurate behavioral baseline data is obtained. Finally, based on the behavioral baseline data, the abnormal detection results of the target behavior are obtained quickly and accurately. In this way, the false alarm rate of abnormal user behavior detection results is reduced, the detection speed is improved, and the audit work needs can be responded to quickly, which can better meet the control of enterprise audit work. Attached Figure Description
[0010] To more clearly illustrate the technical solutions in the embodiments of this application or related technologies, the accompanying drawings used in the description of the related technologies or embodiments will be briefly introduced below. Obviously, the drawings described below only show some embodiments of this application and should not be considered as limiting the scope of protection. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.
[0011] Figure 1 This is a schematic diagram illustrating the application scenarios of the user behavior anomaly detection method in some embodiments of this application; Figure 2 These are schematic diagrams of the structure of electronic devices provided in some embodiments of this application; Figure 3 This is a flowchart illustrating a user behavior anomaly detection method provided in some embodiments of this application; Figure 4 yes Figure 3 A schematic diagram of a sub-process of step S32 in the user behavior anomaly detection method shown in the embodiment; Figure 5 yes Figure 3 A schematic diagram of another sub-process in step S33 of the user behavior anomaly detection method shown in the embodiment. Detailed Implementation
[0012] To make the objectives and advantages of the embodiments of this application more readily understood, the technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of this application, and not all of them. The detailed description of the embodiments of this application in the accompanying drawings is not intended to limit the scope of protection claimed by this application, but only represents selected embodiments of this application. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0013] It should be noted that, unless there is a conflict, the various technical features involved in the embodiments of this application described below can be combined with each other, and all are within the protection scope of this application. Furthermore, although functional modules are divided in the device or structural schematic diagram and a logical order is shown in the flowchart, in some cases, the steps shown or described may be performed in a different order than the module division in the device or the order in the flowchart. In addition, the terms "first," "second," "third," and other similar expressions used herein do not limit the data or execution order, but are only for illustrative purposes and to distinguish identical or similar items with substantially the same function and effect, and should not be construed as indicating or implying relative importance or implicitly specifying the number of technical features.
[0014] Unless otherwise defined, the technical and scientific terms used in this specification have the same meaning as commonly understood by one of ordinary skill in the art to which this application belongs. The terminology used in this specification is for the purpose of describing particular embodiments only and is not intended to limit the scope of this application. It should be understood that the term "and / or" as used in this specification includes any and all combinations of one or more of the listed items.
[0015] With the development of information and digital technologies, the management and operation methods of enterprise auditing have undergone significant changes. Current auditing systems mainly rely on ERP and PMIS systems, which suffer from low auditing efficiency, weak comparative analysis capabilities, and can only perform post-audit results, failing to achieve intelligent risk identification, analysis, and early warning functions. Among related technologies, those for detecting abnormal user behavior suffer from high false alarm rates and slow detection speeds, making it difficult to meet the management and rapid response needs of enterprise auditing.
[0016] In view of this, this application provides a method for detecting abnormal user behavior. By selecting the target dimension and multiple indicator values of the target dimension corresponding to the user's target behavior within the target time window as historical behavior data, the method improves data quality and adapts to different individual users. This allows for the acquisition of accurate behavioral baseline data based on the indicator values of the target dimension. Finally, based on the behavioral baseline data, the method quickly and accurately obtains the abnormal detection results of the target behavior, reducing the false alarm rate of abnormal user behavior detection results, improving detection speed, and enabling rapid response to audit work needs, thus better meeting the control requirements of enterprise audit work.
[0017] Please see Figure 1 , Figure 1 The illustration shows a schematic diagram of an application scenario for the user behavior anomaly detection method provided in some embodiments of this application.
[0018] See Figure 1 As shown, this application scenario includes an electronic device 100 and a host computer 200, with the electronic device 100 communicating with the host computer 200 via a network. It is understood that examples of networks include, but are not limited to, the Internet, corporate intranets, local area networks, mobile communication networks, and combinations thereof.
[0019] In some embodiments, the electronic device 100 obtains historical behavior data from the host computer 200 within a target time window, which corresponds to the user's target behavior and multiple indicator values of the target dimension. In other embodiments, the historical behavior data is stored in the local storage of the electronic device 100, and this embodiment obtains the historical behavior data from the local storage of the electronic device 100.
[0020] After obtaining historical behavior data, this embodiment of the application calculates a score (i.e., data quality score) representing the data quality of the historical behavior data and the distribution characteristics of the indicator values (i.e., target parameter values, including target mean and target standard deviation) based on the historical behavior data, and uses the target parameter values and data quality score as the behavior baseline data.
[0021] For example, after obtaining the behavioral baseline data, the behavioral baseline data is calculated and analyzed to obtain the final anomaly detection result of the target behavior. The anomaly detection result includes anomaly identifier, anomaly level, and anomaly confidence. The anomaly identifier is used to characterize whether the target behavior is abnormal, and the anomaly level is used to characterize the level and confidence of the anomaly when the target behavior is abnormal.
[0022] The above methods can quickly and accurately obtain abnormal detection results of target behavior, reduce the false alarm rate of abnormal user behavior detection results, improve detection speed, and enable rapid response to audit work needs.
[0023] It is understood that electronic device 100 may be a desktop computer, tablet computer, laptop computer, smartphone, or other suitable type of device or apparatus. In some embodiments, electronic device 100 may also be a microcontroller, FPGA chip, or any other suitable component or apparatus. Host computer 200 may be a desktop computer, tablet computer, laptop computer, smartphone, or other suitable type of device or apparatus.
[0024] It should be understood that Figure 1 The application scenarios shown are merely illustrative examples of how user behavior anomaly detection is performed in some embodiments of this application, and do not limit the structure, type, or quantity of the electronic device 100 or the host computer 200 in other application scenarios or embodiments. For example, in Figure 1 In the application scenario shown, electronic device 100 is a laptop computer and host computer 200 is a desktop computer. In other application scenarios or embodiments, electronic device 100 and host computer 200 can also be any other suitable type of device, apparatus or electronic component.
[0025] To facilitate understanding of the user behavior anomaly detection method provided in the embodiments of this application, the electronic device provided in the embodiments of this application will first be described in detail.
[0026] Please see Figure 2 , Figure 2 The schematic diagram illustrates the structure of an electronic device provided in some embodiments of this application.
[0027] like Figure 2 As shown, the electronic device 100 includes at least one processor 110 and a memory 120 connected in communication. Figure 2 Taking a bus system 130 and a processor 110 as an example, the various components in the electronic device 100 are coupled together through the bus system 130, which is used to realize the connection and communication between the various components. It is easy to understand that the bus system 130 may include, in addition to the data bus, a power bus, a control bus, and a status signal bus, etc. However, for the sake of clarity and brevity, in... Figure 2 The general labels all buses as Bus System 130. Understandably, Figure 2 The structures shown in the embodiments are merely illustrative and do not limit the structure of the electronic device described above. For example, the electronic device may also include components that are larger than... Figure 2 The structure shown has more or fewer components, or has the same as Figure 2 The diagram shows different configurations of the structure.
[0028] Specifically, processor 110 provides computational and control capabilities to support electronic device 100 in executing corresponding business logic and functions. For example, it supports electronic device 100 in executing any of the user behavior anomaly detection methods provided in the embodiments of this application, or in executing the steps of any possible implementation of any of the user behavior anomaly detection methods provided in the embodiments of this application. It is understood that processor 110 can be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it can also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components.
[0029] The memory 120, as a non-transitory computer-readable storage medium, can be used to store non-transitory software programs, non-transitory computer-executable programs, instructions, and modules, such as the programs, instructions, and modules corresponding to the user behavior anomaly detection method in the embodiments of this application. In some embodiments, the memory 120 may include a program storage area and a data storage area. The program storage area may store the operating system, applications required for at least one function, and the data storage area may store data created according to the use of the processor 110. The processor 110 executes various functional applications and data processing of the electronic device 100 by running the non-transitory software programs, instructions, and modules stored in the memory 120, so as to implement any of the user behavior anomaly detection methods provided in the embodiments of this application, or execute the steps in any possible implementation of any of the user behavior anomaly detection methods provided in the embodiments of this application. In some embodiments, the memory 120 may include high-speed random access memory and may also include non-transitory memory. For example, at least one disk storage device, flash memory device, or other non-transitory solid-state storage device. In some embodiments, the memory 120 may also include memory remotely located relative to the processor 110, and these remotely located memories may be connected to the processor 110 through a communication network. Understandably, examples of the aforementioned communication networks include, but are not limited to, the Internet, corporate intranets, local area networks, mobile communication networks, and combinations thereof.
[0030] As can be understood from the above, the implementing entity of any user behavior anomaly detection method provided in the embodiments of this application can be any suitable type of electronic device with certain computing and control capabilities, such as the aforementioned electronic device 100. In some feasible implementations, any user behavior anomaly detection method provided in the embodiments of this application can be implemented by a processor executing computer program instructions stored in memory.
[0031] The following will describe in detail the user behavior anomaly detection method provided in this application embodiment, with reference to exemplary applications and implementations of the electronic devices provided in the embodiments of this application.
[0032] Please see Figure 3 , Figure 3 The schematic diagram illustrates a flowchart of a user behavior anomaly detection method provided in some embodiments of this application.
[0033] It is readily understood that the user behavior anomaly detection method provided in this application embodiment can be applied to the aforementioned electronic device (e.g., electronic device 100). Specifically, the execution entity of the user behavior anomaly detection method is one or at least two processors of the electronic device.
[0034] like Figure 3 As shown, the user behavior anomaly detection method includes, but is not limited to, the following steps S31-S33: S31: Obtain historical behavior data.
[0035] In this embodiment, historical behavior data includes the target dimension within the target time window and multiple indicator values for the target dimension. The target dimension is the detection dimension corresponding to the user's target behavior. For example, the target behavior can be operations such as logging into the system, downloading files, or querying data. Correspondingly, the target dimension is the number of system logins, the number of file downloads, and the number of data queries, and the indicator values are the specific numerical values of the number of system logins, the number of file downloads, and the number of data queries.
[0036] For example, when a user performs a target behavior, the electronic device generates corresponding behavior logs (such as login logs, download logs, data access logs, etc.). These behavior logs characterize the user's actual behavior over a historical time period. A target time window is determined based on a preset time length, business cycle, or statistical cycle, and user behavior data within this window is collected from the behavior logs. A target dimension corresponding to the target behavior is determined, and the user behavior data within the target time window is parsed to extract the target dimension. Multiple indicator values for the target dimension are obtained, and the target dimension and its indicator values are used as historical behavior data. It should be understood that the target dimension is used to characterize the detection angle of user behavior, and the indicator values are used to quantify the user's behavioral characteristics under the target dimension.
[0037] In some other embodiments, this application embodiment receives historical behavior data sent by a host computer via a network, thereby obtaining the historical behavior data.
[0038] For example, historical behavioral data is shown in Table 1 below: Table 1:
[0039] According to Table 1, the target time window (10 days) refers to obtaining the target dimension indicator values for 10 consecutive days starting from the current detection date (excluding the current detection date), resulting in multiple indicator values for the target dimension (i.e., the specific value of the number of system logins on each day in the 10 days before the current detection date). For example, the indicator value of the number of system logins on the 1st day in the 10 days before the current detection date is 12, the indicator value of the number of system logins on the 2nd day in the 10 days before the current detection date is 15, ..., and the indicator value of the number of system logins on the 10th day in the 10 days before the current detection date is 11.
[0040] S32: Obtain behavioral baseline data based on historical behavioral data.
[0041] In this embodiment, behavioral baseline data is used to characterize the data quality and distribution characteristics of indicator values of historical behavioral data.
[0042] For example, based on historical behavioral data, data quality analysis is performed on the historical behavioral data to obtain quality parameters used to characterize data quality. These quality parameters include, but are not limited to, data integrity parameters, data consistency parameters, and data validity parameters. It should be understood that data integrity parameters characterize the amount of missing data within the target time window, data consistency parameters characterize the stability of indicator values under the same target dimension, and data validity parameters characterize whether indicator values are within the expected threshold range. Through data quality assessment, it is determined whether the historical behavioral data meets the conditions for constructing behavioral baseline data.
[0043] In some embodiments of this application, when historical behavior data meets preset quality conditions, multiple indicator values of the target dimension are statistically analyzed based on the historical behavior data to obtain the distribution characteristics of the indicator values. These distribution characteristics reflect the user's behavioral patterns within a target time window. The distribution characteristics include, but are not limited to, central tendency characteristics, dispersion characteristics, and distribution pattern characteristics. Central tendency characteristics characterize the overall level of the indicator values, dispersion characteristics characterize the fluctuation range of the indicator values, and distribution pattern characteristics characterize the change patterns of the indicator values.
[0044] For example, behavioral baseline data is constructed based on the distribution characteristics of quality parameters and indicator values. The behavioral baseline data includes baseline parameters describing the range of target-dimensional behavior and corresponding confidence intervals or reference intervals. It is understood that the behavioral baseline data serves as the foundational data for subsequent detection of target behavioral anomalies.
[0045] S33: Based on behavioral baseline data, obtain anomaly detection results for the target behavior.
[0046] For example, the quality parameter values in the behavioral baseline data are compared with a preset quality score threshold, and the distribution characteristic values of the indicator values are compared with a preset distribution characteristic threshold to determine the anomaly detection result of the target behavior. When the quality parameter value is greater than the quality score threshold and the distribution characteristic value of the indicator value is greater than the distribution characteristic threshold, it indicates that the user's target behavior is normal within the target time window, and the anomaly detection result of the target behavior is determined to be normal. When the quality parameter value is less than or equal to the quality score threshold or the distribution characteristic value of the indicator value is less than or equal to the distribution characteristic threshold, it indicates that the user's target behavior is abnormal within the target time window, and the anomaly detection result of the target behavior is determined to be abnormal.
[0047] In some embodiments, the behavioral baseline data can be periodically updated based on a sliding target time window. When the anomaly detection result is normal behavior, the behavioral baseline data can be adaptively corrected to ensure that the behavioral baseline data can continuously reflect the long-term evolution trend of the user's target behavior.
[0048] This application embodiment selects the target dimension and multiple indicator values of the target dimension corresponding to the user's target behavior within the target time window as historical behavior data, thereby improving data quality and adapting to different individual users. Based on the indicator values of the target dimension, accurate behavioral baseline data is obtained. Finally, based on the behavioral baseline data, the abnormal detection results of the target behavior are obtained quickly and accurately. In this way, the false alarm rate of abnormal user behavior detection results is reduced, the detection speed is improved, and the audit work needs can be responded to quickly, which can better meet the control of enterprise audit work.
[0049] Please see Figure 4 , Figure 4 The illustration shows a sub-process diagram of step S32 in the user behavior anomaly detection method provided in some embodiments of this application.
[0050] like Figure 4 As shown, in some embodiments, behavioral baseline data is obtained based on historical behavioral data, specifically including but not limited to the following steps S321-S323: S321: Reference quantity of statistical indicator values.
[0051] In this step, the behavioral baseline data includes target parameter values and a data quality score. The target parameter values are the parameter values of the behavioral baseline corresponding to the target behavior. For example, the target parameter values are the median or average number of system logins in the behavioral baseline. The data quality score is the score for the data quality of historical behavioral data. For example, if the number of indicator values for the target dimension in the historical behavioral data is less than a preset threshold, it indicates that the number of indicator values in the historical behavioral data is insufficient, and the corresponding data quality score is low.
[0052] For example, after obtaining historical behavior data, this application embodiment counts the number of indicator values for the target dimension and uses the number of indicator values for the target dimension as a reference number.
[0053] S322: If the number of response references is greater than or equal to the first preset number threshold, the target parameter value is obtained based on the index value.
[0054] For example, the first preset quantity threshold is 7. When the reference quantity is greater than or equal to the first preset quantity threshold of 7 (i.e., the number of indicator values is greater than or equal to 7), it indicates that the number of indicator values is sufficient and the data quality is high. Then, based on multiple indicator values in the historical behavior data, the target parameter value is calculated. For example, the average value of multiple indicator values is calculated as the target parameter value, and the median of multiple indicator values is selected as the target parameter value.
[0055] In some embodiments, the target parameter value is obtained based on the indicator value, specifically including but not limited to the following step S3221: S3221: Obtain the target mean and target standard deviation based on multiple indicator values.
[0056] In this embodiment of the application, the target parameter values include the target mean and the target standard deviation.
[0057] For example, the average value of multiple indicator values in historical behavioral data is calculated to obtain the target mean. The variance of multiple indicator values in historical behavioral data is calculated to obtain the target variance. Then, the square root of the target variance is taken to obtain the target standard deviation.
[0058] The first formula is as follows: To calculate the target variance, in the first formula, Indicates the target variance. This represents the values of various indicators in historical behavioral data. The target mean, In order to reach a settlement, The reference quantity is the number of indicator values. The meaning of the first formula is to subtract the target mean from each indicator value to obtain the first indicator difference corresponding to that indicator value, then perform an arithmetic square operation on the first indicator difference corresponding to that indicator value to obtain the first square value corresponding to that indicator value, sum the first square values corresponding to all indicator values to obtain the sum of the first square values, and finally divide the sum of the first square values by the reference quantity to obtain the target variance.
[0059] In this embodiment, a target mean and a target standard deviation are obtained based on multiple indicator values. The target mean and target standard deviation are used to accurately characterize the features of historical behavioral data, so that an accurate and reliable data quality score can be calculated subsequently based on the target mean and target standard deviation.
[0060] S323: Obtain a data quality score based on the target parameter values and indicator values.
[0061] For example, after calculating the target parameter values (i.e., the target mean and the target standard deviation), a sample sufficiency score is calculated based on the target parameter values and multiple indicator values in historical behavioral data, and a data quality score is calculated based on the sample sufficiency score.
[0062] In this embodiment, the target parameter value and the target dimension index value are used to calculate the data quality score to evaluate the quality of historical behavior data. When the quality of historical behavior data meets the requirements, behavior baseline data is obtained using historical behavior data. In this way, accurate and reliable behavior baseline data can be obtained, thereby enabling accurate anomaly detection results of target behavior to be obtained based on the behavior baseline data.
[0063] In some embodiments, a data quality score is obtained based on the target parameter value and the indicator value, specifically including but not limited to the following step S3231: S3231: In response to the reference quantity being less than the first preset quantity threshold, the first preset score is determined as the data quality score.
[0064] In some embodiments, the first preset quantity threshold is 7. When the reference quantity is less than the first preset quantity threshold of 7 (i.e., the number of indicator values is less than 7), it indicates that the number of indicator values is insufficient, the data quality is low, and it is impossible to calculate the data quality score based on multiple indicator values in historical behavior data, or the calculated data quality score is unreliable. Therefore, the target parameter value and multiple indicator values in historical behavior data are not used to calculate the data quality score. In this case, the embodiments of this application determine the first preset score set in advance as the data quality score. For example, if the first preset score is 0.3, the first preset score of 0.3 is determined as the data quality score.
[0065] In this embodiment, when the number of indicator values is insufficient, the data quality score is assigned a default first preset score. This ensures the availability of the data quality score, so that a usable data quality score is available when determining the anomaly detection results of the target behavior.
[0066] In some embodiments, a data quality score is obtained based on the target parameter value and the indicator value, specifically including but not limited to the following step S3232: S3232: In response to the target standard deviation being equal to zero, determine the second preset score as the data quality score.
[0067] In some embodiments, when the target standard deviation is equal to zero, it indicates that each of the multiple indicator values in the historical behavioral data is the same, and there is no change in any indicator value. In this case, the embodiments of this application determine a pre-set second preset score as the data quality score. For example, if the second preset score is 0.5, the second preset score of 0.5 is determined as the data quality score.
[0068] In some embodiments, a data quality score is obtained based on the target parameter value and the indicator value, specifically including but not limited to the following steps S3233-S3235: S3233: In response to a reference quantity greater than or equal to a first preset quantity threshold and a target standard deviation greater than zero, a data sufficiency score is obtained based on multiple indicator values.
[0069] For example, when the number of reference values for an indicator is greater than or equal to a first preset threshold and the target standard deviation is greater than zero, it indicates that a data quality score can be normally calculated based on the target parameter value and multiple indicator values in historical behavioral data. Therefore, in this embodiment, a data sufficiency score is first calculated based on multiple indicator values in historical behavioral data.
[0070] In some embodiments, a data sufficiency score is obtained based on multiple indicator values, including but not limited to the following steps S32331-S32332: S32331: Divide the reference quantity of the indicator value by the second preset quantity threshold to obtain the first quotient.
[0071] S32332: The minimum value between the first quotient and the first preset value is determined as the data sufficiency score.
[0072] In this embodiment, the second preset quantity threshold is 30, and the first preset value is 1.0. The reference quantity of the indicator value is divided by the second preset quantity threshold of 30 to obtain the first quotient. The first quotient is compared with the first preset value, and the minimum value between the first quotient and the first preset value is determined. The minimum value between the first quotient and the first preset value is the data sufficiency score.
[0073] For example, if the reference quantity is 9, then the first quotient... Obviously, the minimum of the first quotient value 0.3 and the first preset value 1.0 is the first quotient value 0.3, and the first quotient value 0.3 is determined as the data sufficiency score.
[0074] S3234: Obtain the coefficient of variation based on the target mean and target standard deviation.
[0075] In this embodiment, the coefficient of variation is used to characterize the normalized dispersion of multiple indicator values in historical behavioral data.
[0076] In some embodiments, the coefficient of variation is obtained based on the target mean and the target standard deviation, specifically including but not limited to the following steps S32341-S32342: S32341: Calculate the absolute value of the target mean to obtain the reference mean.
[0077] S32342: Divide the target standard deviation by the reference mean to obtain the coefficient of variation.
[0078] For example, the second formula is as follows: Calculate the coefficient of variation in the second formula. Represents the coefficient of variation. Indicates the target standard deviation. The target mean, The target mean and target standard deviation are used as a reference. The coefficient of variation is calculated by substituting these into the second formula.
[0079] S3235: Obtain a data quality score based on the coefficient of variation and the data sufficiency score.
[0080] For example, a first score difference is obtained by subtracting a preset data sufficiency reference value from the data sufficiency score, and then the data quality score is obtained by multiplying the coefficient of variation by the first score difference. In some embodiments of this application, the data sufficiency reference value is 1.0.
[0081] In this embodiment, data quality scores are flexibly calculated based on different target parameter values and indicator values, thereby obtaining accurate and reliable data quality scores and accurately assessing the quality of historical behavioral data.
[0082] In some embodiments, a data quality score is obtained based on the coefficient of variation and the data sufficiency score, specifically including but not limited to the following steps S32351-S32353: S32351: Subtract the first target value from the first preset value to obtain the first calculated value.
[0083] Wherein, the first target value is the minimum value between the coefficient of variation and the first preset value. In this embodiment of the application, the coefficient of variation is compared with the first preset value to determine the first target value as the minimum value between the coefficient of variation and the first preset value, and the minimum value between the coefficient of variation and the first preset value is used as the first target value.
[0084] In this embodiment, the first preset value is 1. The first target value is subtracted from the first preset value 1.0 to obtain the first calculated value.
[0085] S32352: Multiply the data sufficiency score by the first calculated value to obtain the initial quality score.
[0086] S32353: Determine the second target value as the data quality score.
[0087] In this step, the second target value is the maximum value between the initial quality score and the third preset score, which is 0.1. The initial quality score is compared with the third preset score of 0.1 to determine the maximum value between them, and this maximum value is used as the data quality score.
[0088] In this embodiment, the following third formula is used: And the fourth formula: The coefficient of variation is calculated. In the third formula, Indicates the initial mass fraction. Score the data sufficiency. The coefficient of variation is 1. Indicates request and The minimum value in the fourth formula. Indicates the data quality score. Indicates request and The maximum value in the formula is used. Substituting the coefficient of variation and data sufficiency score into the third formula, the initial quality score is calculated. Substituting the initial quality score into the fourth formula, the data quality score is calculated.
[0089] Please see Figure 5 , Figure 5 The illustration shows a sub-process diagram of step S33 in the user behavior anomaly detection method provided in some embodiments of this application.
[0090] like Figure 5 As shown, in some embodiments, based on behavioral baseline data, anomaly detection results of the target behavior are obtained, specifically including but not limited to the following steps S331-S334: S331: Obtain reference indicator values.
[0091] In this step, the target time window is a time window with a length in days. The target time window corresponds to multiple reference dates ordered chronologically. For example, if the target time window is 10 days and the current detection date is December 15, 2025, then the length of the target time window is 10 days, and the multiple reference dates corresponding to the target time window (ordered chronologically) are December 5, 2025, December 6, 2025, ..., December 13, 2025, and December 14, 2025.
[0092] In this embodiment, the reference index value is the index value of the target dimension on the current detection date. The current detection date is the date that is after the last date among multiple reference dates and adjacent to the last date. As mentioned earlier, the last date among multiple reference dates is December 14, 2025. Therefore, the current detection date is December 15, 2025, which is after the last date December 14, 2025 and adjacent to the last date December 14, 2025.
[0093] For example, the target dimension (such as the number of system logins) has a value of 22 on the current detection date of December 15, 2025, which is the reference value of 22. In this embodiment of the application, the reference value is extracted from the user's behavior log to obtain the reference value.
[0094] S332: Obtain the deviation score based on the first difference and the target standard deviation.
[0095] In this step, the first difference is the difference between the reference indicator value and the target mean. For example, the first difference is obtained by subtracting the target mean from the reference indicator value, and the deviation score is obtained by dividing the first difference by the target standard deviation.
[0096] S333: Determine the target detection direction based on the target dimension.
[0097] In this embodiment, different target dimensions may have different or the same detection directions, thus requiring the determination of the target detection direction for each dimension. The detection direction refers to the relationship between the deviation direction of the indicator value and the probability of anomaly. For example, a larger (or higher) indicator value increases the likelihood of anomalies, so the detection direction is the large value direction or the high value direction; conversely, a smaller (or lower) indicator value increases the likelihood of anomalies, so the detection direction is the small value direction or the low value direction. Specifically, when both larger (or higher) and smaller (or lower) indicator values increase the likelihood of anomalies, the detection direction is the full value direction.
[0098] For example, engineers can pre-design and determine the relationship between different target dimensions and their detection directions based on engineering experience and experimental data. For instance, in some embodiments, the relationship between different target dimensions and their detection directions is shown in Table 2 below: Table 2:
[0099] According to Table 2, when the target dimension is the number of system logins, its detection direction is the direction of large value or high value, that is, the target detection direction of the target dimension is the direction of large value or high value.
[0100] S334: Obtain the anomaly detection result based on the target detection direction and deviation score.
[0101] In this embodiment of the application, different target detection directions may have the same or different anomaly determination thresholds. Therefore, it is necessary to determine the anomaly determination threshold according to the target detection direction, and then compare the deviation score with the anomaly determination threshold to determine the anomaly detection result.
[0102] In this embodiment, the deviation score is calculated using the reference index value of the target dimension on the current detection date. Combined with the target detection direction of the target dimension, the deviation score is accurately determined to determine whether the user's target behavior is abnormal, thus obtaining an accurate abnormal detection result of the target behavior.
[0103] In some embodiments, besides the method provided in this application for calculating deviation scores based on the index values of the target dimension and obtaining anomaly detection results based on the deviation scores, any other suitable method can be used, such as the IQR interquartile range method. Principles of law, etc. This refers to 3 times the target standard deviation, fixed. The threshold is too conservative, resulting in a high false negative rate (capturing only 0.3% of extreme anomalies). Therefore, the method provided in this application, which calculates the deviation score based on the target dimension's index value and obtains the anomaly detection result based on the deviation score, is more suitable and easier to understand. In some specific cases, it can also be chosen... The principle method. The following is a brief explanation of the IQR interquartile range method.
[0104] The IQR interquartile range is a statistical method for measuring dispersion based on quartiles. It is also a common means of identifying outliers in a dataset. Its core principle is to describe the central tendency and dispersion of data through the quartile distribution, without being affected by extreme values.
[0105] Definition of quartiles: Quartiles are three dividing points used to divide sorted data into four equal parts, denoted as the lower quartile (Q1), median (Q2), and upper quartile (Q3). The lower quartile is the value at the 25th percentile of the data after ascending order; it is the maximum value among the first 25% of the data. The median is the value at the 50th percentile of the data after ascending order; it is the median of the data. The upper quartile is the value at the 75th percentile of the data after ascending order; it is the maximum value among the first 75% of the data.
[0106] The formula for calculating the interquartile range (IQR) is: It represents the range of the middle 50% of the data, reflecting the core dispersion of the data, and is not sensitive to extreme values.
[0107] Wherein, the lower threshold is The upper limit threshold is Values in the dataset that are below the lower threshold or above the upper threshold are considered outliers. Applied to the embodiments of this application, when a certain indicator value... satisfy: or If so, the value of the indicator is determined to be an outlier.
[0108] Comparing the method for calculating deviation scores based on target dimension index values and obtaining anomaly detection results based on deviation scores provided in this application's embodiments with the IQR interquartile range method, it can be seen that the method in this application's embodiments is suitable for cases where historical behavior data follows a normal distribution, while the IQR interquartile range method is suitable for cases where historical behavior data has an arbitrary distribution. The computational complexity of the method in this application's embodiments is O(n), while the computational complexity of the IQR interquartile range method is O(n*logn). The threshold in the method in this application's embodiments is adjustable, while the threshold in the IQR interquartile range method is fixed at 1.5 times. Since the historical behavior data in this application's embodiments follows a normal distribution, the method of calculating deviation scores based on target dimension index values and obtaining anomaly detection results based on deviation scores is more suitable and faster.
[0109] In some embodiments, methods such as Isolation Forest or LSTM time series prediction can also be used to obtain anomaly detection results based on the target dimension index values. However, the Isolation Forest method requires more than 30 days of target dimension index values for training, does not support cold start, has low interpretability, and high computational cost. The LSTM time series prediction method has high training cost, high data requirements, requires more than 90 days of target dimension index values, and its real-time performance is worse than that of the method in the embodiments of this application. The method selected in the embodiments of this application is applicable to user entity behavior analysis scenarios, can provide interpretable detection and judgment basis, saves computational and training costs, has low data requirements, and can quickly obtain anomaly detection results.
[0110] In some embodiments, anomaly detection results are obtained based on the target detection direction and deviation score, including but not limited to the following steps S3341-S3343: S3341: Determine the anomaly identifier and the first anomaly level based on the target detection direction and deviation score.
[0111] In this embodiment, the anomaly detection result includes a first detection result and a second detection result. The first detection result includes an anomaly identifier, a first anomaly level, and an anomaly confidence level. The second detection result includes a second anomaly level. In some embodiments, the anomaly detection result also includes explanatory information describing the anomaly detection result using natural language, such as explanatory information about the first anomaly level, the anomaly confidence level, and the second anomaly level.
[0112] In some embodiments, an anomaly identifier and a first anomaly level are determined based on the target detection direction and the deviation score, specifically including but not limited to the following steps S33411-S33414: S33411: In response to the target detection direction and deviation score satisfying any one of the first detection condition, the second detection condition and the third detection condition, the abnormality identifier is determined as the first identifier.
[0113] In this step, the first detection condition is that the target detection direction is the first direction and the deviation score is greater than a preset multiple threshold. The second detection condition is that the target detection direction is the second direction and the deviation score is less than the negative of the preset multiple threshold. The third detection condition is that the target detection direction is the third direction and the absolute value of the deviation score is greater than the preset multiple threshold. The first identifier is used to characterize abnormal user target behavior, and the third direction includes both the first and second directions.
[0114] For example, a preset multiplier threshold of 2 is used. When the target detection direction is the first direction and the deviation score is greater than the preset multiplier threshold of 2, the anomaly identifier is determined as the first identifier. Alternatively, when the target detection direction is the second direction and the deviation score is less than the opposite of the preset multiplier threshold (-2 in this embodiment), the anomaly identifier is determined as the first identifier. Alternatively, when the target detection direction is the third direction and the absolute value of the deviation score is greater than the preset multiplier threshold of 2, the anomaly identifier is determined as the first identifier.
[0115] S33412: In response to the absolute value of the deviation score being greater than the first score threshold, the first anomaly level is determined as the first level.
[0116] S33413: In response to the absolute value of the deviation score being greater than the second score threshold and less than or equal to the first score threshold, the first abnormality level is determined as the second level.
[0117] S33414: In response to the absolute value of the deviation score being greater than the third score threshold and less than or equal to the second score threshold, the first anomaly level is determined to be the third level.
[0118] In this embodiment, the first score threshold is 6.0, the second score threshold is 4.0, and the third score threshold is 2.0. After determining that user behavior is abnormal (i.e., the abnormality identifier is the first identifier), when the absolute value of the deviation score is greater than the first score threshold of 6.0, the first abnormality level is determined to be the first level. When the absolute value of the deviation score is greater than the second score threshold of 4.0 and less than or equal to the first score threshold of 6.0, the first abnormality level is determined to be the second level. When the absolute value of the deviation score is greater than the third score threshold of 2.0 and less than or equal to the second score threshold of 4.0, the first abnormality level is determined to be the third level. The risk of the first level is greater than that of the second level, and the risk of the second level is greater than that of the third level.
[0119] For example, the first level is critical, the second level is advanced, and the third level is intermediate. The risk of critical level is greater than that of advanced level, and the risk of advanced level is greater than that of intermediate level.
[0120] In this embodiment, by combining the target detection direction and the deviation score, an accurate and reliable anomaly identifier and a first anomaly level are obtained, thereby obtaining an accurate and reliable anomaly detection result for the target behavior.
[0121] S3342: Obtain the anomaly confidence level based on the data quality score, the number of references, and the deviation score.
[0122] In this embodiment, the data quality score, the number of reference values for the indicator, and the deviation score are fused together to obtain the anomaly confidence score, which is used to characterize the credibility of the anomaly detection results. By comprehensively considering the magnitude of the deviation, data quality, and sample sufficiency, the anomaly confidence score is output, making the anomaly detection results more reliable.
[0123] In some embodiments, the anomaly confidence level is obtained based on the data quality score, the number of references, and the deviation score, specifically including but not limited to the following steps S33421-S33424: S33421: Obtain the confidence level of the deviation based on the deviation score.
[0124] For example, a preset reference value of 4 is set, and the deviation score is divided by the preset reference value of 4 to obtain the deviation confidence level.
[0125] In some embodiments, the deviation confidence level is obtained based on the deviation score, specifically including but not limited to the following steps S334211-S334212: S334211: Divide the deviation score by the fourth score threshold to obtain the second quotient.
[0126] S334212: The minimum value among the second quotient and the first preset value is determined as the deviation confidence level.
[0127] In this embodiment, the fourth score threshold is 5. A fourth score threshold of 5 indicates that the deviation score is completely reliable when it is greater than 5 target standard deviations. The first preset value is 1.0.
[0128] For example, the deviation score is divided by the fourth score threshold to obtain the second quotient. The second quotient is compared with the first preset value 1.0 to determine the minimum value between the second quotient and the first preset value 1.0. The minimum value between the second quotient and the first preset value 1.0 is the deviation confidence level.
[0129] S33422: Determine the data quality score as the data quality confidence level.
[0130] S33423: Determine the data sufficiency score as the data sufficiency confidence level.
[0131] S33424: The anomaly confidence level is obtained by weighted fusion of the bias confidence level, data quality confidence level, and data sufficiency confidence level.
[0132] For example, a weight is assigned to each of the bias confidence level, data quality confidence level, and data sufficiency confidence level. The bias confidence level is multiplied by its weight to obtain the first product. The data quality confidence level is multiplied by its weight to obtain the second product. The data sufficiency confidence level is multiplied by its weight to obtain the third product. Finally, the first, second, and third products are added together to obtain the anomaly confidence level. It can be understood that the sum of the weights of the bias confidence level, data quality confidence level, and data sufficiency confidence level equals 1.
[0133] In some embodiments, the deviation confidence score, data quality confidence score, and data sufficiency confidence score are weighted and fused to obtain the anomaly confidence score, specifically including but not limited to the following steps S334241-S334246: S334241: Multiply the bias confidence level by the first weighting coefficient corresponding to the bias confidence level to obtain the first product value.
[0134] S334242: Multiply the data quality confidence level by the second weight coefficient corresponding to the data quality confidence level to obtain the second product value.
[0135] S334243: Multiply the data sufficiency confidence level by the third weight coefficient corresponding to the data sufficiency confidence level to obtain the third product value.
[0136] S334244: Add the first product value, the second product value, and the third product value to obtain the initial confidence level.
[0137] In this system, the sum of the first, second, and third weighting coefficients equals 1. For example, the first weighting coefficient could be 0.5, the second weighting coefficient 0.3, and the third weighting coefficient 0.2. Of course, the first, second, and third weighting coefficients can also be any other suitable weighting values.
[0138] S334245: The minimum value between the initial confidence level and the standard confidence level threshold is determined as the first confidence level.
[0139] S334246: The maximum value among the first confidence level and the reference confidence level threshold is determined as the abnormal confidence level.
[0140] In this embodiment, the standard confidence threshold is 1.0 and the reference confidence threshold is 0.1.
[0141] Specifically, the initial confidence level is compared with the standard confidence threshold of 1.0 to determine the minimum of the two. This minimum is the first confidence level. Then, the first confidence level is compared with the reference confidence threshold of 0.1 to determine the maximum of the two. This maximum is the outlier confidence level.
[0142] S3343: Determine the second abnormality level based on the reference indicator value and multiple indicator values.
[0143] In this embodiment, abnormal user behavior is detected at different time lengths to distinguish between short-term fluctuations and long-term trend deviations. A portion of indicator values are extracted from multiple indicators, and a deviation ratio is calculated based on the portion of indicator values and a reference indicator value. The second abnormality level is then determined based on the deviation ratio.
[0144] In this embodiment, the deviation ratio is obtained by combining the target reference index value and multiple index values, and the second anomaly level is accurately determined based on the deviation ratio to obtain an accurate and reliable second anomaly level, thereby obtaining an accurate and reliable anomaly detection result of the target behavior.
[0145] In some embodiments, a second anomaly level is determined based on a reference indicator value and multiple indicator values, specifically including but not limited to the following steps S33431-S33433: S33431: Extract at least one indicator value of the target dimension located within the candidate time window from multiple indicator values as the first indicator value.
[0146] In this embodiment, the length of the candidate time window is less than or equal to the length of the target time window, and the length of the candidate time window is at least one day. The candidate time window corresponds to at least one base date ordered chronologically, and the last date among the at least one base date is the same as the last date among multiple reference dates. That is, the candidate time window also obtains the index values for a continuous corresponding time length starting from the current detection date. For example, if the candidate time window is 3 days and the current detection date is December 15, 2025, then the candidate time window obtains the index values of the target dimension for 3 consecutive days starting from the current detection date, December 15, 2025. The at least one base date (ordered chronologically) corresponding to the candidate time window is December 12, 2025, December 13, 2025, and December 14, 2025.
[0147] For example, at least one indicator value of the target dimension located within the candidate time window is extracted from multiple indicator values as the first indicator value. For example, if the candidate time window is 3 days, at least one indicator value of the target dimension located within the candidate time window is extracted from multiple indicator values (i.e., the indicator value of the target dimension for the three consecutive days obtained from the current detection date of December 15, 2025 (i.e., the indicator values of the target dimension on December 12, 2025, December 13, 2025, and December 14, 2025) as the first indicator value).
[0148] S33432: Obtain the deviation ratio based on the first indicator value and the reference indicator value.
[0149] For different candidate time windows, the number of target dimension indicator values (i.e., first indicator values) selected within the candidate time window varies. Different deviation ratios need to be calculated based on one or more first indicator values and reference indicator values.
[0150] In some embodiments, the deviation ratio is obtained based on the first index value and the reference index value, specifically including but not limited to the following steps S334321-S334323: S334321: Determine candidate indicator values from the first indicator values.
[0151] Here, the candidate metric value is the metric value of the target dimension on the candidate date. The candidate date is a date within the candidate time window that is before the current detection date and adjacent to the current detection date. For example, if the current detection date is December 15, 2025, the candidate time window is 3 days, and the candidate time window has at least one candidate date (sorted in chronological order) that is December 12, 2025, December 13, 2025, and December 14, 2025, then the candidate date is December 14, 2025, which is within the candidate time window (i.e., December 12, 2025, December 13, 2025, and December 14, 2025) and is before the current detection date of December 15, 2025 and adjacent to the current detection date of December 15, 2025.
[0152] For example, the first indicator value of the target dimension within the candidate time window (i.e., the indicator values of the target dimension on December 12, 2025, December 13, 2025, and December 14, 2025) determines the indicator value of the target dimension on the candidate date (i.e., December 14, 2025), and the indicator value of the target dimension on the candidate date (i.e., December 14, 2025) is used as the candidate indicator value.
[0153] S334322: The response first indicator value includes an indicator value of the target dimension. The reference indicator value is subtracted from the candidate indicator value to obtain the second difference value.
[0154] S334323: Divide the second difference by the candidate index value to obtain the deviation ratio.
[0155] Specifically, when the first indicator value of the target dimension within the selected candidate time window includes only one indicator value of the target dimension (i.e., the candidate time window is 1 day), only the indicator value of the target dimension on the corresponding base date (i.e., December 14, 2025) is selected. In this case, the base date is the candidate date. Subtracting the candidate indicator value from the reference indicator value yields the second difference. Dividing the second difference by the candidate indicator value yields the deviation ratio.
[0156] In some embodiments, the deviation ratio is obtained based on the first index value and the reference index value, specifically including but not limited to the following steps S334324-S334326: S334324: The response first indicator value includes multiple indicator values of the target dimension. The average value of the multiple indicator values of the target dimension is calculated to obtain the candidate mean value.
[0157] S334325: Subtract the candidate mean from the reference index value to obtain the third difference.
[0158] S334326: Divide the third difference by the candidate mean to obtain the deviation ratio.
[0159] Specifically, when the first indicator value of the target dimension within the selected candidate time window includes only multiple indicator values of the target dimension (i.e., the candidate time window is multiple days), the indicator values of the target dimension on multiple reference dates corresponding to the candidate time window are selected. In this case, the candidate date is December 14, 2025, which is the date that is before the current detection date (i.e., December 15, 2025) and adjacent to the current detection date (i.e., December 15, 2025). The average value of the multiple indicator values of the target dimension is calculated to obtain the candidate mean. The reference indicator value is subtracted from the candidate mean to obtain the third difference. The third difference is divided by the candidate mean to obtain the deviation ratio.
[0160] S33433: Determine the second abnormality level based on the deviation ratio.
[0161] For example, the deviation ratio is compared with a preset ratio threshold range. When the deviation ratio is within the corresponding ratio threshold range, the abnormality level corresponding to the ratio threshold range is set as the second abnormality level.
[0162] In some embodiments, a second anomaly level is determined based on the deviation ratio, including but not limited to the following steps. S334331: If the absolute value of the response deviation ratio is greater than or equal to the first preset ratio, the second anomaly level is determined as the first target level.
[0163] S334332: If the absolute value of the response deviation ratio is greater than or equal to the second preset ratio and less than the first preset ratio, the second anomaly level is determined as the second target level.
[0164] S334333: If the absolute value of the response deviation ratio is greater than or equal to the third preset ratio and less than the second preset ratio, the second anomaly level is determined as the third target level.
[0165] In this embodiment, the first preset ratio is 3.0, the second preset ratio is 1.0, and the third preset ratio is 0.5. The absolute value of the deviation ratio is compared with the first preset ratio of 3.0, the second preset ratio of 1.0, and the third preset ratio of 0.5. When the absolute value of the deviation ratio is greater than or equal to the first preset ratio of 3.0, the second anomaly level is determined to be the first target level. When the absolute value of the deviation ratio is greater than or equal to the second preset ratio of 1.0 and less than the first preset ratio of 3.0, the second anomaly level is determined to be the second target level. When the absolute value of the deviation ratio is greater than or equal to the third preset ratio of 0.5 and less than the second preset ratio of 1.0, the second anomaly level is determined to be the third target level. For example, the first target level is a high level, the second target level is a medium level, and the third target level is a low level. The risk of the high level is greater than that of the medium level, and the risk of the medium level is greater than that of the low level.
[0166] In this embodiment, different deviation ratios are obtained based on the indicator values of the target dimension at different time scales (i.e., the indicator values of the target dimension in candidate time windows of different time lengths). Based on the deviation ratios, different anomalies are detected, and the impact of short-term fluctuations and long-term trend deviations is distinguished. For example, when the candidate time window is 1 day, sudden anomalies (such as brute-force attacks) are captured; when the candidate time window is 3 days, occasional data fluctuations on a single day are filtered out; when the candidate time window is 7 days, weekly indicator value change trends are identified; and when the candidate time window is 30 days, changes in users' long-term behavioral patterns are identified.
[0167] In summary, the user behavior anomaly detection method provided in this application improves data quality and adapts to different individual users by selecting the target dimension and multiple indicator values of the target dimension corresponding to the user's target behavior within the target time window as historical behavior data. This allows for the acquisition of accurate behavioral baseline data based on the indicator values of the target dimension, and ultimately, the rapid and accurate anomaly detection results of the target behavior based on the behavioral baseline data. As a result, the false alarm rate of user behavior anomaly detection results is reduced, the detection speed is improved, and the ability to quickly respond to audit work needs is enhanced, thus better meeting the control requirements of enterprise audit work.
[0168] The following describes the beneficial effects of the user behavior anomaly detection method provided in this application, based on actual experimental data: 1) Improved detection accuracy: Experimental environment: 100 users from a certain enterprise, 30 days of historical behavior data, 50 target dimensions. The experimental data is shown in Table 3 below: Table 3:
[0169] According to Table 3, the accuracy improved from 96.6% to 99.5% (+2.9%, i.e., an increase of 2.9%), the false positive rate decreased from 1.8% to 0.39% (-78%, i.e., a decrease of 78%), and the F1-Score improved from 0.569 to 0.935 (+64%, i.e., an increase of 64%).
[0170] 2) Adaptive data quality effect: Scenario 1: Automatic downgrading when there are insufficient samples, as shown in Table 4 below: Table 4:
[0171] Scenario 2: Filtering when data fluctuations are too large, as shown in Table 5 below: Table 5:
[0172] According to Tables 4 and 5, the false alarm rate decreased from 8.5% to 0.39% (-95%, i.e., a reduction of 95%).
[0173] 3) Improved coverage across multiple time granularities: Experiment: Anomaly coverage of 50 target dimensions. The experimental data is shown in Table 6 below: Table 6:
[0174] According to Table 6, the anomaly coverage rate of a single time granularity is only 40%, while the anomaly coverage rate of multi-time granularity fusion is increased to 100%.
[0175] This application provides a computer-readable storage medium storing processor-executable computer program instructions. When executed by a processor, the computer program instructions cause the computer to perform the user behavior anomaly detection method provided in this application, or to perform the steps in any possible implementation of the user behavior anomaly detection method provided in this application.
[0176] This application provides a computer program product, which includes a computer program stored on a computer-readable storage medium. The computer program includes a program or instructions. When the instructions or program are executed by an electronic device, the electronic device performs the user behavior anomaly detection method provided in this application, or performs the steps in any possible implementation of the user behavior anomaly detection method provided in this application.
[0177] Those skilled in the art will understand that the embodiments provided in this application are merely illustrative. The order in which the steps in the methods of the embodiments are written does not imply a strict execution order and does not constitute any limitation on the implementation process. The order can be adjusted, merged, and deleted according to actual needs. Modules or sub-modules, units or sub-units in the apparatus or system of the embodiments can be merged, divided, and deleted according to actual needs. For example, the division of units is only a logical functional division, and there may be other division methods in actual implementation. For another example, multiple units or components can be combined or integrated into another device, or some features can be ignored or not executed.
[0178] Through the above description of the embodiments, those skilled in the art will clearly understand that each embodiment can be implemented using software plus a general-purpose hardware platform, and of course, it can also be implemented using hardware. Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. This computer program can be stored in a computer-readable storage medium, and when executed, it can include the processes of the embodiments of the above methods. It should be understood that the storage medium can be flash memory, hard disk, optical disk, register, magnetic surface memory, removable disk, CD-ROM, random access memory (RAM), read-only memory (ROM), electrically programmable ROM, and electrically erasable programmable ROM, etc.
[0179] It should be noted that the above embodiments are for illustrating the technical concept and features of this application, and are intended to enable those skilled in the art to understand the content of this application and implement it accordingly. They should not be construed as limiting the scope of protection of this application. Those skilled in the art can understand that all or part of the processes of the above embodiments can be implemented, modified according to the technical solutions described in the embodiments of this application, or equivalent substitutions can be made to some of the technical features. It is understood that these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of this application, and should be considered as equivalent changes and modifications made based on the embodiments of this application, all of which should fall within the scope of the claims of this application.
Claims
1. A method for detecting abnormal user behavior, characterized in that, The method includes: Acquire historical behavior data, wherein the historical behavior data includes a target dimension within a target time window and multiple indicator values of the target dimension, wherein the target dimension is a detection dimension corresponding to the user's target behavior; Based on the historical behavioral data, behavioral baseline data is obtained, which is used to characterize the data quality of the historical behavioral data and the distribution characteristics of the indicator values. Based on the baseline behavioral data, anomaly detection results for the target behavior are obtained.
2. The method according to claim 1, characterized in that, The behavioral baseline data includes target parameter values and data quality scores. The target parameter values are the parameter values of the behavioral baseline corresponding to the target behavior, and the data quality scores are the data quality scores of the historical behavioral data. Obtaining the behavioral baseline data based on the historical behavioral data includes: Calculate the reference number of the aforementioned indicator values; When the reference quantity is greater than or equal to a first preset quantity threshold, the target parameter value is obtained based on the indicator value; The data quality score is obtained based on the target parameter value and the indicator value.
3. The method according to claim 2, characterized in that, Obtaining the target parameter value based on the indicator value includes: Based on the multiple indicator values, the target mean and target standard deviation are obtained; The target parameter values include the target mean and the target standard deviation.
4. The method according to claim 3, characterized in that, The step of obtaining the data quality score based on the target parameter value and the indicator value includes: In response to the reference quantity being less than the first preset quantity threshold, the first preset score is determined as the data quality score; or, In response to the target standard deviation being equal to zero, a second preset score is determined as the data quality score; or, In response to the reference quantity being greater than or equal to the first preset quantity threshold and the target standard deviation being greater than zero, a data sufficiency score is obtained based on multiple indicator values; The coefficient of variation is obtained based on the target mean and the target standard deviation; The data quality score is obtained based on the coefficient of variation and the data sufficiency score.
5. The method according to any one of claims 3-4, characterized in that, The target time window is a time window with a length in days. The target time window corresponds to multiple reference dates sorted in chronological order. Obtaining the anomaly detection result of the target behavior based on the behavioral baseline data includes: Obtain reference index values, wherein the reference index values are the index values of the target dimension on the current detection date, and the current detection date is the date that is after the last date among a plurality of reference dates and adjacent to the last date; A deviation score is obtained based on the first difference and the target standard deviation, wherein the first difference is the difference between the reference index value and the target mean; Based on the target dimension, determine the target detection direction for that target dimension; The anomaly detection result is obtained based on the target detection direction and the deviation score.
6. The method according to claim 5, characterized in that, The anomaly detection result includes a first detection result and a second detection result. The first detection result includes an anomaly identifier, a first anomaly level, and an anomaly confidence level. The second detection result includes a second anomaly level. Obtaining the anomaly detection result based on the target detection direction and the deviation score includes: Based on the target detection direction and the deviation score, the anomaly identifier and the first anomaly level are determined; The anomaly confidence level is obtained based on the data quality score, the number of references, and the deviation score. The second anomaly level is determined based on the reference indicator value and multiple indicator values.
7. The method according to claim 6, characterized in that, The step of determining the anomaly identifier and the first anomaly level based on the target detection direction and the deviation score includes: In response to the target detection direction and the deviation score satisfying any one of a first detection condition, a second detection condition, and a third detection condition, the anomaly identifier is determined to be a first identifier. The first detection condition is that the target detection direction is a first direction and the deviation score is greater than a preset multiple threshold. The second detection condition is that the target detection direction is a second direction and the deviation score is less than the opposite of the preset multiple threshold. The third detection condition is that the target detection direction is a third direction and the absolute value of the deviation score is greater than the preset multiple threshold. The first identifier is used to characterize the user's target behavior anomaly. The third direction includes the first direction and the second direction. In response to the absolute value of the deviation score being greater than a first score threshold, the first anomaly level is determined to be the first level; In response to the absolute value of the deviation score being greater than a second score threshold and less than or equal to the first score threshold, the first anomaly level is determined as the second level; In response to the absolute value of the deviation score being greater than a third score threshold and less than or equal to the second score threshold, the first abnormality level is determined to be the third level.
8. The method according to claim 6, characterized in that, The step of obtaining the anomaly confidence level based on the data quality score, the number of references, and the deviation score includes: The deviation confidence level is obtained based on the deviation score; The data quality score is determined as the data quality confidence level; The data sufficiency score is determined as the data sufficiency confidence level; The anomaly confidence level is obtained by weighted and fused the deviation confidence level, the data quality confidence level, and the data sufficiency confidence level.
9. The method according to claim 6, characterized in that, Determining the second anomaly level based on the reference indicator value and multiple indicator values includes: At least one indicator value of the target dimension located within a candidate time window is extracted from the plurality of indicator values as a first indicator value, wherein the time length of the candidate time window is less than or equal to the time length of the target time window, the candidate time window corresponds to at least one reference date ordered in chronological order, and the last date of at least one of the reference dates is the same as the last date of the plurality of reference dates; The deviation ratio is obtained based on the first indicator value and the reference indicator value; The second anomaly level is determined based on the deviation ratio.
10. The method according to claim 9, characterized in that, Determining the second anomaly level based on the deviation ratio includes: If the absolute value of the deviation ratio is greater than or equal to a first preset ratio, the second anomaly level is determined to be the first target level. If the absolute value of the deviation ratio is greater than or equal to the second preset ratio and less than the first preset ratio, the second anomaly level is determined to be the second target level. If the absolute value of the deviation ratio is greater than or equal to a third preset ratio and less than a second preset ratio, the second anomaly level is determined to be the third target level.
11. An electronic device, characterized in that, include: A processor and a memory communicatively connected to the processor; The memory stores computer program instructions executable by the processor, and the processor executes the computer program instructions to cause the electronic device to perform the user behavior anomaly detection method as described in any one of claims 1-10.
12. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores processor-executable computer program instructions, which the processor executes to cause the computer to perform the user behavior anomaly detection method as described in any one of claims 1-10.
13. A computer program product, characterized in that, The computer program product includes a computer program stored on a computer-readable storage medium, the computer program including programs or instructions that, when executed by an electronic device, cause the electronic device to perform the order behavior risk detection method as described in any one of claims 1-10.